SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-77017

HIGH · CVSS 7.7 EPSS 0.25%

Source: NVD + CISA KEV + EPSS · Published 2026-08-27 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

The Workeera WordPress plugin prior to version 1.0.6 is vulnerable due to insufficient restrictions on profile value submissions and file storage locations, enabling users with minimal permissions, such as subscribers, to access arbitrary files on the server. This can lead to exposure of sensitive information, including configuration files and authentication secrets. WordPress site administrators and security teams should prioritize this vulnerability to mitigate potential data breaches.

CVE
CVE-2026-77017
Severity
HIGH
CVSS
7.7
EPSS
0.25%
WordPress

Original NVD Description

The Workeera WordPress plugin before 1.0.6 does not restrict which profile values a candidate may submit, nor confine the stored file location to an allowed directory before serving it, allowing users with a role as low as subscriber to read arbitrary files on the server, including its configuration file and authentication secrets.